Sceawere
Vulnerability Detail
CVE-2026-61203Updated Verified Sceawere Triage Sources: NVD / CISA KEV
PeopleSoft Expenses Unauthenticated Data Compromise
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.4
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise FIN Expenses
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Expenses accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Expenses accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Expenses.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Expenses accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Expenses accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Expenses. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.4",
"pubDate": "2026-07-21T22:18:52.063Z",
"pubdate": "2026-07-21T22:18:52.063Z",
"executiveSummary": "This vulnerability affects the Oracle PeopleSoft Enterprise FIN Expenses component, specifically version 9.2. It is characterized as a critical-severity security flaw with a CVSS 3.1 base score of 9.4, indicating substantial risk to organizational data and system availability.\nThe vulnerability allows an unauthenticated, remote attacker with network access to exploit the Expenses component via the HTTP protocol. Successful exploitation grants the attacker extensive unauthorized access to critical data, enabling the creation, modification, or deletion of sensitive information within the application. Furthermore, the attacker can induce a partial denial-of-service (DoS) condition, disrupting service availability.\nGiven that the exploit requires no user interaction and does not necessitate prior authentication, it poses a high risk to the confidentiality, integrity, and availability (CIA triad) of the PeopleSoft environment. Organizations utilizing affected versions must prioritize remediation to prevent full data compromise or unauthorized administrative-level data manipulation.",
"technicalDetails": "The vulnerability resides within the PeopleSoft Enterprise FIN Expenses component, specifically affecting the 9.2 version architecture. The root cause pertains to an improper access control or authentication bypass mechanism that permits unauthorized HTTP-based interactions with internal application functions.\nThe attack vector is characterized as remote and network-based, utilizing standard HTTP communication channels. Because the vulnerability exhibits an 'Access Complexity: Low' (AC:L) attribute, an attacker can reliably initiate the exploit without needing specialized environmental conditions or complex target-specific configurations. The lack of required 'Privileges' (PR:N) or 'User Interaction' (UI:N) significantly lowers the barrier to entry, allowing for automated or scriptable exploitation attempts.\nThe attack flow follows a direct interaction pattern: An attacker crafts a malicious HTTP request directed at the vulnerable Expenses component interface. By bypassing expected session validation or authorization checks, the attacker can invoke backend functions designed for expense management, reporting, or data lifecycle administration. This allows the attacker to bypass standard application-level security controls.\nPost-exploitation, the impact is severe. The integrity of the system is compromised, allowing for the unauthorized modification or deletion of financial records. Confidentiality is breached as the attacker gains the ability to exfiltrate critical enterprise data processed within the application. Additionally, the ability to trigger a partial denial of service suggests that the attacker can exhaust system resources or disrupt transactional logic, preventing legitimate users from accessing or processing expenses.\nTechnically, the vulnerability indicates a failure to enforce authorization logic on endpoints that handle sensitive data operations. Because the scope (S:U) is unchanged, the impact is confined to the PeopleSoft Enterprise FIN Expenses application itself, but the resulting risk to the underlying data stores is absolute within the context of that application's reach. The vulnerability demonstrates that the application fails to validate the identity of the requester before executing high-impact business logic, effectively exposing internal APIs to the public or untrusted network segment."
}